Data and Compliance
Law 18-07: A Practical Data-Protection Checklist for Algerian Companies
A practical path to inventory processing, clarify purposes, manage rights, and document technical and organizational measures.

Decision supported
An operational data-protection programme starts from real processing activities: purpose, people, data, recipients, retention, security, processors, and transfers. Then organise notices, rights requests, applicable formalities, incident handling, and evidence of compliance.
Important note
This operational checklist does not replace legal advice or a formal assessment of the processing activities and requirements applicable to your organisation.
Executive summary
- Law 18-07 of 10 June 2018 governs personal-data processing in Algeria.
- Law 25-11 of 24 July 2025 amended and supplemented it, including concepts related to biometrics, profiling, pseudonymisation, and data breaches.
- ANPDP provides portals for processing organisations and for complaints or appeals.
- Compliance must be documented per processing activity and integrated into projects, contracts, operations, and incidents.
The framework to use in August 2026
Read Law 18-07 together with its amendments, applicable implementing texts, ANPDP procedures, and sector duties. Separate legal requirements from Atlas implementation recommendations.
Legal boundary
This brief is an operational reading, not legal advice. Confirm obligations and formalities for each processing activity.
1. Inventory processing, not only databases
- Name the purpose and business owner.
- List people and data categories.
- Record sources, recipients, processors, and transfers.
- Define retention and deletion.
- Link systems, access, and security measures.
2. Make individual rights executable
Provide an intake route, verify identity proportionately, locate data across systems, record decisions, and test access, correction, objection, and deletion workflows end to end.
3. Link security to processing risk
Classify data and exposure, minimise access, log sensitive actions, protect transfers and backups, test restoration, and document residual risk rather than applying a generic checklist.
4. Govern processors, transfers, and SaaS
Verify purpose, instructions, security, subcontracting, incident duties, location, deletion, audit evidence, and exit before granting access to personal data.
5. Prepare for a data breach
Define detection, containment, evidence, legal assessment, communication, notification decisions, remediation, and ownership before an incident occurs.
Composite example: a sales form that became a permanent database
A short campaign form can become uncontrolled processing when data is copied into CRM, spreadsheets, messaging tools, and exports with no retention owner. Map the full flow, not the original form alone.
Decisions to make now
Recommended actions
- 01Appoint an internal programme owner and legal, security, and business contacts.
- 02Inventory the ten most sensitive or largest processing activities.
- 03Compare public notices with actual tools and flows.
- 04Test an access request and account deletion end to end.
- 05Review key processor contracts and applicable ANPDP procedures.
- 06Run a data-breach exercise and record gaps.
Watch points
- A consolidated text and new ANPDP guidance.
- Practical operation of regional control and audit units introduced in 2025.
- Sector requirements for biometrics, profiling, and transfers.
Frequently asked questions
Was Law 18-07 replaced?
No. It was amended and supplemented, notably by Law 25-11 of 24 July 2025. Use the current framework as a whole.
Can a professional email address be personal data?
Yes, when it directly or indirectly identifies a natural person. Assess context and content.
Is a supplier certification sufficient?
No. It is partial evidence; assess scope, configuration, contracts, transfers, access, and your own use.
Sources and verification
Last editorial verification: 4 August 2026. Links point to the source texts, authorities, and reference guides consulted.
- 01Loi no 18-07 du 10 juin 2018
Journal officiel de la République algérienne. Accessed 4 August 2026.
- 02Loi no 25-11 du 24 juillet 2025
Journal officiel de la République algérienne. Accessed 4 August 2026.
- 03Notice d’information relative aux données à caractère personnel
ANPDP. Accessed 4 August 2026.
- 04Portail des organismes traitant des données à caractère personnel
ANPDP. Accessed 4 August 2026.
Related decisions
Continue with briefs that share the same operational, technical, or governance context.
Data and Compliance
AI Readiness: Verify Data, Processes, and Infrastructure
Read the briefCybersecurity
Risk-Adjusted ROI: Include Errors, Security, and Vendor Dependency
Read the briefField Operations
Offline-First Field Software: A Decision Protocol for Reliable Operations
Read the briefMove from decision to execution
Frame a reliable product or business system.
Atlas Technology supports the scoping, architecture, delivery, and production launch of B2B software in Algeria.